AI just changed CX. Most teams haven't noticed yet. See what you're missing
Trust center

Enterprise-grade from day one.

Bold on the front end. Rigorous underneath. Cozmo is built to clear IT and security review early — with privacy, auditability, and governance designed in, so your buying process never stalls.

ISO 27001 SOC 2 Type 2 GDPR-aligned processing Encrypted in transit & at rest Responsible AI policy
Trust areas

Core trust areas.

What sits under governance, and who reviews it.

Security management

A formal information security management system: risk assessment, policies, training, and continuous improvement.

Data protection

Encryption, secure hosting architecture, controlled access, and data handling procedures.

Access control

Role-based access, least-privilege principles, and administrative controls.

Privacy

DPA, privacy policy, data subject request process, subcontractor transparency, and customer-controller support.

Responsible AI

Defined usage principles, governance, human oversight, and policy documentation.

Business continuity

Operational resilience, backup, recovery, and incident response controls.

Vendor management

Subcontractor review, security requirements, and change notification practices.

Customer options

Contractual and configuration options for customer-specific security and retention requirements, subject to scope and agreement.

Controls

How we protect your data.

ISO 27001

A formal information security management system: risk assessment, policies, training, and continuous improvement.

SOC 2 Type 2

SOC 2 Type 2 controls for security and availability.

GDPR-aligned processing

Data minimization, consent management, and privacy by design.

Encryption

Data encrypted in transit and at rest.

Role-based access

RBAC with separation of personal from statistical data where applicable.

Audit trail

Every insight traces back to its source. Audit trail for recommendations and source evidence.

Responsible AI

Explainable recommendations with evidence and reasoning behind every Action Card.

Documents

Trust center documents.

Everything your security, legal, and procurement teams need for evaluation.

The Privacy Policy, Data Processing Agreement, Responsible AI Usage Policy, Subcontractors List, and Data Subject Request Form are published in full, alongside the SaaS Terms, the CCPA notice, and the Accessibility Statement.

Go to our Legal page
A note on GDPR

GDPR is a legal framework, not a product certification.

Cozmo is a Howazit product. Howazit supports GDPR-aligned processing and acts as a data processor under customer instructions, with contractual safeguards documented in our DPA.